gpupdate /force killed my DC

I was adding permissions to a specific user on my Win2K3 box and decided to
user gpupdate /force to apply the new permissions to the user. When I
rebooted, most of my services failed to start. Now even the Administrator
account doesn't have permissions to either Domain Controller Security Policy
or Domain Security Policy. When I try to use Active Directory User's and
Groups I get "Naming information cannot be located because: The specified
domain either does not exist or could not be contacted." Since most of my
services are dead, I don't have any network connections. When I tried to
use dcpromo to demote the DC, it quit indicating that it couldn't use the
File Replication service because it depended on other service (which aren't

What happened? How can get my services running a become a real Administrator
with enough power to get myself out of this mess without re-installing



Relevant Pages

  • Re: Publishing Software...
    ... I may have to recant my thoughts about it being a permissions issue, ... domain workstation security policy and then lock it down and reapply that. ... >> Are the users on the machines in question, members of the local Administrators group?? ... >> User Rights configuration was completed with one or more errors. ...
  • Re: HTML embbeded (via <object> tag) Strong FullTrust Assemblies f
    ... Nicole, thank you for all of your precise help. ... >> Can an assembly with internet permissions running as an embedded object, ... > You seem to be mixing up the .NET Framework security policy and the IE ... You will most likely need to alter the client machine's .NET ...
  • Re: security managment and policy monitoring
    ... >enable me to verify that an organization's security policy is being ... and in NT this would be the files that comprise the SAM database ... Once you have _all_ the data about files and permissions gathered, ... Then there's no single place where the relevant files might reside, ...
  • Re: Okay.. what is going on here .. Security error?
    ... and changed the local intranet permissions setting - ... > against the security policy, and a permission grant is generated. ... > there is a more restrictive policy placed on LocalIntranet assemblies. ...
  • Re: Users cannot change passwords
    ... Security Policy [or possibly local on a domain controller] the security ... change password permissions to the user object in Active Directory. ... I have looked for a group policy, ...